Re: Challenges from challenge-response systems qualify as unsolicited

From: Nick Landsberg (hukolau_at_NOSPAM.att.net)
Date: 04/07/04


Date: Wed, 07 Apr 2004 01:32:15 GMT

Alan Connor wrote:

> On Wed, 07 Apr 2004 00:30:30 GMT, Nick Landsberg <hukolau@NOSPAM.att.net> wrote:
>
>>
>>John-Paul Stewart wrote:
>>
>>
>>>Alan Connor wrote:
>>>
>>
>>[Everything Snipped]
>>
>>Pardon for coming into this thread late, but
>>I have what I think is an honest question.
>>
>>I thought it was "conventional wisdom" (whatever
>>that is) that any kind of response to a spammer
>>only encourages them to send more? ("Hey,
>>I found a live Email addy, I can sell this
>>addy to the next spammer down the street!")
>>The end-result being that more and more SPAM
>>is generated to your addy for your machine to
>>filter (wasting CPU cycles while doing so).
>>
>>Or maybe I don't understand what is meant
>>by a challenge/response system?
>>
>
>
> The only people who do here, are all the spammers
> posing as spamhaters in order to discredit the
> one type of filter they can't beat.

My pardons, but there is nothing that is
unbeatable. If you believe there is, you
need a dose of reality. From other
posts here and from personal knowledge,
once one can forge either "From:" headers
or "Reply To:" headers one has beaten it.

>
> They do this regularly.
>
> No one that I know of uses JUST C/Rs in their filters.
>
> First, they run the mail through a passlist, making
> sure that they get all the mail they KNOW they want
> to get.

Easily done.

>
> Next, the rest is sent through a filter like SpamAssassin
> where the mail that is indisputably spam is sent to
> /dev/null.

I don't trust SpamAssassin or anything of that ilk
because it has been known to block Emails about
pending bills I have to pay. While programs such
as this try to "learn" about the spam, the spammers
"learn" how to mimic legitimate emails. What
happens is that legitimate Emails get categorized
as spam. Sending my Visa bill statement to /dev/null
is not an option for me.

>
> And LASTLY, the mail that might or might not be spam
> is sent a C/R.
>
> Twice. If no return is received from that address the
> second time it shows up, it is blocked and any further
> mail from that address goes straight to /dev/null.

And if the "From:" line or the "Reply To:" line is
forged? Or if the bank sending out my Visa bill
specifically says "Do not reply to this Email" because
they have an automated system which is not monitored
and all replies go to /dev/null?

>
> It is important, when using a system like this to
> passlist ANYONE you send mail to, to prevent C/R
> loops.
>
> See my lengthier description on this thread.
>
> AC

IMHO, all these attempts are treating symptoms
rather than causes. Treating the actual
causes may be more than just a technical
problem.

-- 
"It is impossible to make anything foolproof
because fools are so ingenious"
  - A. Bloch


Relevant Pages

  • Re: spam traps
    ... >> it...maybe I can try using it in my Outlook Express newsgroup account. ... > But you said you want to view the spam in case any legitimate emails are ... > through spamassassin to get rid of the more obvious spam. ... Even with the ISP's spam filter (which in my case is ...
    (alt.os.linux.redhat)
  • A little bit off topic but...A general question about SPAM/Antivirus software?
    ... mechanism that looks at your outgoing and incoming emails ... has keyword filter, header malformed filter and a few ... I have spam routed to a SPAM email folder that I peruse ... through to make sure I don't get any false positives. ...
    (microsoft.public.exchange.misc)
  • Re: Alias email...
    ... public and then filter (and by filter I mean setting up a safe sender ... to remove any spam and only forward valid emails through to my real ... Exchange or if I have to use a third party software like a spam ... Your company might consider outsourcing the spam filtering to a third party ...
    (microsoft.public.exchange2000.general)
  • Re: John Wart Jr
    ... I get 5-700 spam emails a day and am unwilling to give up my email ... Depends on the spam filter. ... need to only check the quarantine log which might hold 2-3% of the ...
    (rec.games.pinball)
  • RE: OMA and Outgoing Spam
    ... Someone hacked a user account and use it to spam emails; ... Your Exchange server is open relaying emails;(You have checked it ... Your server is under RNDR Attack. ... Microsoft is providing this information as a convenience to you. ...
    (microsoft.public.windows.server.sbs)